All Apps and Add-ons

"No spec file" errors when trying to deploy Splunk Add-on for VMware from the index master node

keio_splunk
Splunk Employee
Splunk Employee

VMware data collection is working fine but when pushing out Splunk Add-on for VMware from the index master node the following warnings are reported:
[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_esxilogs/default/eventgen.conf
[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_vcenter/default/eventgen.conf

alt text

splunkd.log:
WARN CMBundleMgr - Bundle validation warnings bundle=/app/splunk/var/run/splunk/cluster/remote-bundle/2ea968f32581661ba4910e8e0322176f-1542938006.bundle, err=[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_esxilogs/default/eventgen.conf\n;[Not Critical]No spec file for: /app/splunk/etc/master-apps/Splunk_TA_vcenter/default/eventgen.conf\n

Why are the warnings generated?

0 Karma
1 Solution

keio_splunk
Splunk Employee
Splunk Employee

The warnings thrown by the cluster master is expected behavior and can be safely ignored.
The eventgen.conf in Splunk_TA_esxilogs and Splunk_TA_vcenter are used for generating dummy data along with SA-Eventgen which will provide the spec file(eventgen.conf.spec).

View solution in original post

keio_splunk
Splunk Employee
Splunk Employee

The warnings thrown by the cluster master is expected behavior and can be safely ignored.
The eventgen.conf in Splunk_TA_esxilogs and Splunk_TA_vcenter are used for generating dummy data along with SA-Eventgen which will provide the spec file(eventgen.conf.spec).

Get Updates on the Splunk Community!

Maximize the Value from Microsoft Defender with Splunk

 Watch NowJoin Splunk and Sens Consulting for this Security Edition Tech TalkWho should attend:  Security ...

This Week's Community Digest - Splunk Community Happenings [6.27.22]

Get the latest news and updates from the Splunk Community here! News From Splunk Answers ✍️ Splunk Answers is ...

Reminder! Splunk Love Promo: $25 Visa Gift Card for Your Honest SOAR Review With ...

We recently launched our first Splunk Love Special, and it's gone phenomenally well, so we're doing it again, ...